CoreVocab 核心字庫 隱私權政策
生效日期:2026 年 10 月 3 日
CoreVocab 核心字庫(以下稱「本 App」)由 Candan Weng(以下稱「開發者」或「我」)開發,提供 iPhone、iPad 與 Mac 使用。這份政策用白話說明本 App 會處理哪些資料、存在哪裡、會不會離開你的裝置。
重點摘要
- 不需要帳號、不用登入。 本 App 沒有註冊流程,也沒有開發者自己的伺服器。
- 沒有廣告、沒有分析工具、沒有追蹤。 本 App 不含任何廣告、數據分析、當機回報或其他會蒐集資料的第三方 SDK,也不會跨 App 或跨網站追蹤你。
- 你的學習資料留在你的裝置上,以及(如果你開啟 iCloud 同步)你自己的 iCloud 私人資料庫裡。開發者看不到這些資料。
- AI 解析與例句都在裝置上產生。 你輸入的答案不會傳到任何 AI 伺服器。
- 唯一會固定連網傳出內容的功能是線上發音:要唸出來的英文單字或句子會送到 Microsoft 的語音服務。你可以在設定裡改用完全離線的系統語音。
1. 存在你裝置上的資料
為了讓本 App 運作,下列資料會存在你的裝置上(App 的沙盒、系統的偏好設定儲存空間 UserDefaults,以及 App Group 共用空間):
- 學習進度與複習排程(間隔重複演算法 FSRS 的參數)
- 設定
- 每日統計與作答紀錄
- 程度測驗結果與推估的程度
- 自訂單字表
- AI 產生的卡片與你回報有問題的卡片
App Group 共用空間只讓本 App 自己的「主畫面小工具」和「分享延伸功能」讀取,用來顯示今天要複習幾張卡,以及暫存你從其他 App 分享過來、還沒匯入的文字。
這些資料不會傳給開發者或任何第三方。刪除本 App 時,裝置上的這些資料也會一併刪除。
2. iCloud 同步(可關閉)
iCloud 同步預設開啟,可以在 App 的「設定 › iCloud 同步」關閉。
開啟時,你的學習進度、產生過的卡片、統計、自訂單字與推估程度,會存到你自己的 iCloud 帳號裡的 CloudKit 私人資料庫(容器名稱 iCloud.dev.candan.corevocab),讓你在自己的多台裝置之間同步。設定不會同步。
- 私人資料庫只有登入同一個 Apple 帳號的你能存取,開發者無法讀取。
- 這些資料會佔用你的 iCloud 儲存空間。
- iCloud 由 Apple 提供,適用 Apple 隱私權政策。
如何刪除 iCloud 上的資料:
- 在 App 裡「設定 › 重設所有學習進度」:會清除這台裝置和 iCloud 上的進度,其他同步中的裝置也會一起清除;或
- iPhone / iPad:「設定 › [你的名字] › iCloud › 管理帳號儲存空間」(部分系統版本叫「管理儲存空間」),找到 CoreVocab 後刪除資料;Mac:「系統設定 › [你的名字] › iCloud › 管理」。
3. AI 功能(全部在裝置上執行)
本 App 用 AI 產生答錯時的解析,以及新單字的例句:
- 支援 Apple Intelligence 的裝置:使用 Apple 的 Foundation Models 框架,在裝置上產生內容。
- 其他裝置:你可以選擇下載 Google 的 Gemma 4 E2B 模型(約 2.4 GB),之後完全在你的裝置上執行。模型檔從 Hugging Face(
huggingface.co/litert-community/...)下載;跟任何檔案下載一樣,下載時 Hugging Face 會看到你的 IP 位址等一般連線資訊,適用 Hugging Face 隱私權政策。下載完成後,使用模型不需要連網。如果你也裝了同一位開發者的 InsightRSS,兩個 App 可能共用同一份模型檔,只共用模型檔本身,不共用學習資料。
不論哪一種,你輸入的答案、作答紀錄都不會傳到任何 AI 伺服器。
4. 發音
- 預設:Microsoft 線上神經語音。 要唸出的英文單字或例句文字,會透過網路送到 Microsoft 的語音服務,換回語音檔播放。本 App 不會附上任何能識別你的資訊(沒有帳號、裝置識別碼或作答紀錄),但 Microsoft 跟任何網路服務一樣會收到你的 IP 位址等一般連線資訊,適用 Microsoft 隱私權聲明。
- 系統語音(離線)。 沒有網路或連不上時,本 App 會自動改用裝置內建的系統語音;你也可以在「設定 › 發音」直接改成系統語音,這樣就不會送出任何內容。
5. 匯入單字
- MDX 字典檔:你從「檔案」App 選擇的 .mdx 檔只在裝置上讀取,不會上傳。
- 剪貼簿:只有在你按下「從剪貼簿匯入」時,本 App 才會讀取剪貼簿內容。
- 分享選單:你從其他 App 分享文字給本 App 時,文字會暫存在 App Group 共用空間,直到本 App 匯入。
6. 通知與小工具
- 每日複習提醒是在裝置上排程的本機通知,沒有推播伺服器。你可以隨時在 App 設定或系統設定中關閉。
- 主畫面小工具只讀取 App Group 共用空間裡的資料,不會連網。
7. App 內購買
本 App 可免費使用,並提供一次性的「解鎖完整版」買斷(非消耗型項目),解除每日新字與 AI 解析的數量限制。
付款完全由 Apple 處理。本 App 只透過 Apple 的 StoreKit 收到「是否已購買」的交易與權限資訊,拿不到你的付款資料、姓名或 Apple 帳號。購買適用 Apple 隱私權政策。
8. 診斷紀錄與聯絡支援
本 App 的診斷區有「複製程度測驗紀錄」和「複製作答紀錄」按鈕,只會把紀錄複製到你的剪貼簿,不會自動傳送到任何地方。如果你想請開發者協助,可以自己決定是否把這些紀錄貼到 Email 裡寄來。
你寫信給開發者時,開發者會收到你的 Email 地址和信件內容(包括你自行貼上的紀錄),只會用來回覆你的問題,不會用於行銷,也不會提供給第三方。如果你希望刪除往來信件,來信告知即可。
9. Apple 提供的資訊
如果你在裝置的系統設定裡同意「與 App 開發者分享」分析資料,Apple 可能會依它的政策,把匿名、彙總後的當機報告與使用統計提供給開發者。這是 Apple 系統層級的功能,不是本 App 蒐集的,你可以隨時在系統設定裡關閉。
10. 兒童隱私
本 App 分級為 4 歲以上,不會蒐集任何人的個人資料,包括兒童。
11. 你的權利
因為開發者沒有保存你的學習資料,所以沒有可以讓開發者查詢、匯出或刪除的帳號資料。你可以隨時自行刪除資料:在 App 裡重設進度、在 iCloud 管理儲存空間裡刪除,或直接刪除本 App。
12. 政策變更
如果本 App 處理資料的方式有變動,我會更新這份政策並修改上方的生效日期。重大變更會在 App 更新說明中告知。
13. 聯絡方式
對這份政策有任何問題,請寫信到:candanweng@gmail.com
CoreVocab: English Vocabulary — Privacy Policy
Effective date: October 3, 2026
CoreVocab: English Vocabulary ("CoreVocab" or "the app") is developed by Candan Weng ("the developer", "I") for iPhone, iPad and Mac. This policy explains, in plain language, what data the app handles, where it is stored, and whether it ever leaves your device.
Summary
- No account, no sign-in. There is no registration, and the developer runs no servers for the app.
- No ads, no analytics, no tracking. The app contains no advertising, analytics, crash-reporting or other data-collecting third-party SDKs, and it does not track you across apps or websites.
- Your learning data stays on your device, plus (if you turn on iCloud sync) in your own private iCloud database. The developer cannot see it.
- AI explanations and example sentences are generated on your device. Nothing you type is sent to an AI server.
- The only feature that regularly sends content over the internet is online pronunciation: the English word or sentence to be spoken is sent to Microsoft's speech service. You can switch to fully offline system voices in Settings.
1. Data stored on your device
To work, the app stores the following on your device (in the app's sandbox, in the system's UserDefaults, and in an App Group container):
- Learning progress and review schedule (parameters for the FSRS spaced-repetition algorithm)
- Settings
- Daily statistics and answer history
- Placement test results and your estimated level
- Your custom word lists
- AI-generated cards and cards you have reported as having a problem
The App Group container is shared only with the app's own Home Screen widget and Share extension. It is used to show how many cards are due today, and to hold text you shared from another app until the app imports it.
None of this is sent to the developer or any third party. Deleting the app deletes this data from your device.
2. iCloud sync (optional)
iCloud sync is on by default. You can turn it off in the app under Settings › iCloud sync.
When it is on, your learning progress, generated cards, statistics, custom words and estimated level are stored in the CloudKit private database in your own iCloud account (container iCloud.dev.candan.corevocab) so they sync across your devices. Settings are not synced.
- The private database is accessible only to you, signed in with your Apple Account. The developer cannot read it.
- This data counts against your iCloud storage.
- iCloud is provided by Apple and is covered by Apple's Privacy Policy.
How to delete your iCloud data:
- In the app, Settings › Reset all progress clears your progress on this device and in iCloud, which also clears it on your other synced devices; or
- On iPhone / iPad: Settings › [your name] › iCloud › Manage Account Storage (called "Manage Storage" on some system versions), find CoreVocab and delete its data. On Mac: System Settings › [your name] › iCloud › Manage.
3. AI features (all on-device)
The app uses AI to explain your mistakes and to write example sentences for new words:
- On devices that support Apple Intelligence, it uses Apple's Foundation Models framework, which runs on your device.
- On other devices, you can choose to download Google's Gemma 4 E2B model (about 2.4 GB), which then runs entirely on your device. The model is downloaded from Hugging Face (
huggingface.co/litert-community/...). As with any download, Hugging Face sees ordinary connection information such as your IP address; Hugging Face's Privacy Policy applies. Once downloaded, the model works without an internet connection. If you also have InsightRSS, another app by the same developer, the two apps may share one copy of the model file. Only the model file is shared, never your learning data.
Either way, your answers and answer history are never sent to any AI server.
4. Pronunciation
- Default: Microsoft online neural voices. The text of the English word or sentence to be spoken is sent over the internet to Microsoft's speech service, which returns audio. The app adds no information that identifies you (no account, device identifier or answer history), but like any online service Microsoft receives ordinary connection information such as your IP address. The Microsoft Privacy Statement applies.
- System voices (offline). If you are offline or the service can't be reached, the app automatically falls back to your device's built-in voices. You can also switch to system voices in Settings › Pronunciation, in which case nothing is sent.
5. Importing words
- MDX dictionary files: a .mdx file you pick from the Files app is read only on your device and never uploaded.
- Clipboard: the app reads the clipboard only when you tap the import-from-clipboard button.
- Share Sheet: text you share to the app from another app is held in the App Group container until the app imports it.
6. Notifications and widget
- Daily study reminders are local notifications scheduled on your device. There is no push server. You can turn them off at any time in the app or in system Settings.
- The Home Screen widget reads only data in the App Group container and does not connect to the internet.
7. In-app purchase
The app is free to use, with a one-time "unlock full version" purchase (non-consumable) that removes the daily limits on new words and AI explanations.
Payment is handled entirely by Apple. Through Apple's StoreKit, the app only receives transaction and entitlement information telling it whether you have purchased. It never receives your payment details, name or Apple Account. Purchases are covered by Apple's Privacy Policy.
8. Diagnostics and contacting support
The diagnostics section of the app has "Copy placement test log" and "Copy answer history" buttons. They only copy the log to your clipboard. Nothing is sent anywhere automatically. If you want help from the developer, it is up to you whether to paste these logs into an email.
When you email the developer, the developer receives your email address and the content of your message (including any logs you choose to paste). These are used only to answer your question, never for marketing, and are not shared with third parties. If you would like our correspondence deleted, just ask.
9. Information provided by Apple
If you have agreed in your device's system settings to "Share with App Developers", Apple may, under its own policies, provide the developer with anonymous, aggregated crash reports and usage statistics. This is a system-level Apple feature, not data collected by the app, and you can turn it off at any time in system settings.
10. Children's privacy
The app is rated 4+ and does not collect personal data from anyone, including children.
11. Your rights
Because the developer keeps none of your learning data, there is no account data for the developer to look up, export or delete. You stay in control: reset your progress in the app, delete the data from iCloud storage management, or delete the app.
12. Changes to this policy
If the way the app handles data changes, I will update this policy and the effective date above. Significant changes will be mentioned in the app's release notes.
13. Contact
Questions about this policy? Email candanweng@gmail.com.
沒有留言:
張貼留言